CVE-2020-6655 - CVE House
Back to Database
Status published Medium CVE-2020-6655

File parsing Out-Of-Bounds read remote code execution

Vulnerability Description

The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The vulnerability arises due to improper validation and parsing of the E70 file content by the application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-6655

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Eaton would like to thank Francis Provencher from ZDI

Affected Vendor

Affected Software

easySoft Software
Vulnerable Versions:
v7.xx prior to v7.22

Timeline

Official Publish: January 7th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

Weaknesses (CWE)